cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1774
Views
5
Helpful
2
Replies

VTP Best Practices

HMidkiff
Level 1
Level 1

I have a pretty good size network. A MDF and 6 IDF's. In the past I configured all my IDF's as their own VLAN. All ports going out to the IDF's were configured for particular VLAN's and this worked pretty well. Due to some internal changes I am going to reconfigure my connection ports as trunks, so I will have the ability to put a specific VLAN on any port in the company. As part of this I will be using VTP. I have a few questions regarding the configuration of VTP. Here they are:

1. I have several offices where I will be deploying VTP. Should I use a separate VTP domain in each office?

2. Should I enable VTP pruning?

3. Should I use a VTP password?

4. Is there any way to configure a second VTP server for redundancy?

5. Any best practices anyone can recommend?

2 Replies 2

Edison Ortiz
Hall of Fame
Hall of Fame

I have several offices where I will be deploying VTP. Should I use a separate VTP domain in each office?

If the offices are inter-connected via a routed WAN Link, you can use the same VTP domain in each office as the Layer2 information won't be forwarded over the WAN.

If the offices are inter-connected via a Metro-E or any other Layer2 WAN service, then having an unique VTP domain in each office is highly recommended.

Should I enable VTP pruning?

Yes.

Should I use a VTP password?

Yes.

. Is there any way to configure a second VTP server for redundancy?

Of course, you can have multiple switches serving as VTP server. Just set the mode to VTP server on more than one switch and they will share the VTP DB.

Any best practices anyone can recommend?

If you want to go with VTP for ease of Vlan management, VTP pruning and VTP password are the 2 most important aspect to address.

However, VTP Server/Client configuration is frown upon many organizations. One mistake made on the VTP server Vlan DB can cause disruption in the whole VTP domain. Often, it's recommended to go with VTP transparent all around but this means you will have to manage each switch's Vlan database independently.

HTH,

__

Edison.

Please rate helpful posts

Hi,

just one note:

Using the same VTP domain (and password) in more sites can be a little dangerous.

Moving a switch (even a VTP client) from one office to another can bring a "VTP bomb" there.

BR,

Milan

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card